StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

2026-08-19T13:23:59Z4c0f5f9a5049728bec366c40dcc732481a21b76e4dd0998616878df142f1089a
CVE-2026-15748CVE-2026-19478CVE-2026-58231CVE-2026-59310CVE-2026-65400AI-securityAPTGitLabMLflowMicrosoft-SharePointMicrosoft-TeamsRaySAP-Commerce-CloudSCADA-OTVMware-vCenterWordPressactive-exploitationbotnetcloud-securitycredential-theftdata-theftinformation-stealermacOSmalwareprompt-injectionransomwaresupply-chain-securitytyposquattingvulnerabilitiesweb-shell

What happened

The document is a cybersecurity news digest covering active exploitation of critical vulnerabilities, malware and botnet campaigns, credential and data theft, ransomware activity, supply-chain and cloud security issues, AI-agent threats, and enterprise platform compromises. Notable incidents include exploitation of macOS Screen Sharing, VMware vCenter, SAP Commerce Cloud, MLflow, Ray, GitLab, and WordPress Forminator vulnerabilities, along with campaigns abusing hacked websites, trusted Microsoft services, RubyGems typosquatting, and macOS stealer infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4c0f5f9a5049728bec366c40dcc732481a21b76e4dd0998616878df142f1089a
Enrichment time
2026-08-19T13:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.